Messages by Thread
-
CVE-2026-82561: Apache NiFi: Missing Authorization for Components Referenced in Flow Update Methods
David Handermann
-
CVE-2026-81866: Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Connector Configuration
David Handermann
-
CVE-2026-87976: Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles
David Handermann
-
CVE-2026-70469: Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HTTP Requests
David Handermann
-
[ANNOUNCE] Apache Fory 1.7.3 released
Shawn Yang
-
[ANNOUNCE] Apache BookKeeper 4.18.1 released
Matteo Merli
-
[ANN] Apache Tomcat 9.0.122 available
Rémy Maucherat
-
CVE-2026-82311: Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int _user_id comparison is always false
Vincent Beck
-
CVE-2026-86465: Apache Airflow Akeyless provider: Akeyless secrets backend: team-scope guard bypass via user-controlled key
Vincent Beck
-
CVE-2026-82310: Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core API JWT access
Vincent Beck
-
CVE-2026-86466: Apache Airflow FAB provider: FAB Authentik provider: id_token issuer/audience not validated
Vincent Beck
-
CVE-2026-76187: Apache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWT
Vincent Beck
-
CVE-2026-76186: Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity
Vincent Beck
-
CVE-2026-86792: Apache Airflow Apache Kafka provider: Connection-editor remote code execution on the Scheduler via Kafka connection callback configuration
Vincent Beck
-
CVE-2026-86462: Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-backed sessions
Vincent Beck
-
CVE-2026-84439: Apache ZooKeeper: Audit log injection via unsanitized output from multiple sources
Andor Molnar
-
CVE-2026-79993: Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode
Andor Molnar
-
CVE-2026-84501: Apache ZooKeeper: Operational log forgery via newline injection in EnsembleAuthenticationProvider
Andor Molnar
-
CVE-2026-59739: Apache ZooKeeper: Information disclosure via SetWatches reconnect replay
Andor Molnar
-
CVE-2026-59969: Apache ZooKeeper: Improper validation of certificate with host mismatch in FIPS mode
Andor Molnar
-
[ANN] Apache Tomcat 11.0.26 Available
Mark Thomas
-
[ANN] Apache Tomcat 10.1.60 Available
Christopher Schultz
-
[ANNOUNCE] OpenDAL 0.59.2-rc.2 released
xuanwo
-
CVE-2026-73191: Apache Syncope: CAS service URL injection via Forwarded HTTP headers
Francesco Chicchiriccò
-
[ANNOUNCE] Apache Airflow Providers prepared on 2026-09-09 are released
Vincent Beck
-
CVE-2026-87785: Apache Syncope: JWT subject spoofing
Francesco Chicchiriccò
-
CVE-2026-82232: Apache Syncope: SQL injection via sort parameter in Task search
Francesco Chicchiriccò
-
CVE-2026-75030: Apache Syncope: Incomplete authorization checks for Group members deprovisioning
Francesco Chicchiriccò
-
CVE-2026-77883: Apache Syncope: Information disclosure via one-hop JEXL navigation past the JexlContextBuilder name denylist
Francesco Chicchiriccò
-
CVE-2026-77181: Apache Syncope: ClientApp update entitlement not effective
Francesco Chicchiriccò
-
CVE-2026-78318: Apache Syncope: Unauthenticated reflected XSS in Console and Enduser
Francesco Chicchiriccò
-
CVE-2026-87779: Apache Syncope: AES Secret Key disclosure via log output
Francesco Chicchiriccò
-
CVE-2026-68570: Apache Doris: Authorization bypass leading to unauthorized data access
Calvin Kirs
-
CVE-2026-72524: Apache Doris: Authorization bypass allowing a low-privilege user to read/write/drop arbitrary tables
Calvin Kirs
-
CVE-2026-78330: Apache Syncope: Privilege escalation for admin user via JWT authentication
Francesco Chicchiriccò
-
CVE-2026-78336: Apache Syncope: OIDCC4UI provider list discloses client secrets to any authenticated user
Francesco Chicchiriccò
-
CVE-2026-86460: Apache Syncope: Cypher Injection via FIQL Search on Neo4j Persistence
Francesco Chicchiriccò
-
CVE-2026-87802: Apache Syncope: SRA OAuth2 JWT signature verification bypass
Francesco Chicchiriccò
-
[ANN] Apache Syncope 4.1.3
Francesco Chicchiriccò
-
[ANN] Apache Syncope 4.0.8
Francesco Chicchiriccò
-
CVE-2026-73195: Apache Syncope: CSV export spreadsheet formula injection
Francesco Chicchiriccò
-
CVE-2026-73370: Apache Syncope: Cross-Realm boundaries reconciliation bypass
Francesco Chicchiriccò
-
CVE-2026-73236: Apache Syncope: Cross-Realm authorization bypass in delegated administration
Francesco Chicchiriccò
-
CVE-2026-73178: Apache Syncope: JWT Access Token takeover
Francesco Chicchiriccò
-
CVE-2026-73470: Apache Syncope: Delegating users can grant unowned Roles
Francesco Chicchiriccò
-
CVE-2026-73668: Apache Syncope: Cross-realm disclosure of confidential ConnId bundles configuration values
Francesco Chicchiriccò
-
CVE-2026-73579: Apache Syncope: Non-recursive Any search could skip Realms restrictions
Francesco Chicchiriccò
-
CVE-2026-77051: Apache Syncope: SQL injection via unsanitized entityKey and opEvent in Audit Events search
Francesco Chicchiriccò
-
CVE-2026-75015: Apache Syncope: Nested secrets leak cleartext into audit records readable
Francesco Chicchiriccò
-
[ANNOUNCE] Apache Camel Karaf 4.18.4 has been released!
Jean-Baptiste Onofré
-
[ANNOUNCE] Apache IoTDB 2.0.11 released
Haonan Hou
-
[ANNOUNCE] Apache Groovy 6.0.0-RC-2 Released
Paul King
-
CVE-2026-82432: Apache Storm Nimbus: Blobstore Authorization Bypass via Rebalance Configuration Overrides
Richard Zowalla
-
CVE-2026-82428: Apache Storm Client: Cross-Tenant Dependency Jar Substitution via Predictable Blob Keys
Richard Zowalla
-
CVE-2026-82427: Apache Storm Nimbus: Path Traversal as the Supervisor User via Unsanitised Blobstore Map Local Name
Richard Zowalla
-
CVE-2026-82431: Apache Storm Client: Authorization Bypass When nimbus.groups Is Configured Without nimbus.users
Richard Zowalla
-
CVE-2026-82437: Apache Storm Logviewer: Log Access Controls Not Enforced by Logviewer
Richard Zowalla
-
CVE-2026-82433: Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Daemon Configuration via Nimbus and the UI
Richard Zowalla
-
CVE-2026-82435: Apache Storm Worker: Unauthenticated Remote Memory Exhaustion in the Worker Messaging Decoder
Richard Zowalla
-
CVE-2026-82429: Apache Storm Worker Launcher: Local Privilege Escalation to Root via a Time-of-Check Race in the Worker Launcher
Richard Zowalla
-
CVE-2026-82426: Apache Storm Nimbus: Arbitrary File Read on Nimbus via Unvalidated Uploaded Jar Location
Richard Zowalla
-
CVE-2026-82430: Apache Storm Worker Launcher: Local Privilege Escalation to Root via Container Command Files Chowned to the Tenant
Richard Zowalla
-
CVE-2026-82434: Apache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to Logs
Richard Zowalla
-
CVE-2026-82439: Apache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPC
Richard Zowalla
-
CVE-2026-82438: Apache Storm Webapp: Authenticated API Responses Exposed to Arbitrary Web Origins
Richard Zowalla
-
CVE-2026-82441: Apache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service via Unvalidated Topology Dependency Keys
Richard Zowalla
-
CVE-2026-84179: Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon Configuration via the Topology Page
Richard Zowalla
-
[ANNOUNCE] Apache Storm 3.1.0 released
Rui Abreu
-
[ANNOUNCE] OpenNLP 2.5.12 and 3.0.0-M6 released
Richard Zowalla
-
CVE-2026-82617: Apache OpenNLP: ReDoS / stack exhaustion in RegexNameFinderFactory built-in EMAIL and URL patterns
Richard Zowalla
-
CVE-2026-67211: Apache OpenNLP: OOM DoS via Unbounded Array Allocation in SymSpellModelSerializer
Richard Zowalla
-
[ANNOUNCE] Apache Fory 1.7.2 released
Shawn Yang
-
CVE-2026-80354: Apache Camel K: Camel K Builder trait mavenProfiles ValueSources resolve tenant-named secrets in operator namespace
Pasquale Congiusti
-
CVE-2026-80352: Apache Camel K: Camel K Master trait serviceAccountName YAML injection lets CR author apply arbitrary objects
Pasquale Congiusti
-
CVE-2026-80351: Apache Camel K: Camel K Tenant repositories reach Maven execution inside operator pod
Pasquale Congiusti
-
[ANNOUNCE] Apache Commons BCEL Version 6.13.0
Gary Gregory
-
CVE-2026-49362: Apache Artemis, Apache ActiveMQ Artemis: Missing Authentication in CORE Protocol Handler Allows Unauthorized Queue Creation
Clebert Suconic
-
CVE-2026-57967: Apache Artemis, Apache ActiveMQ Artemis: Missing authentication on CORE protocol session reattachment
Clebert Suconic
-
CVE-2026-67593: Apache Artemis, Apache ActiveMQ Artemis: Pre-authentication Openwire protocol handling can result in queue deletion
Clebert Suconic
-
CVE-2026-49364: Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Cluster Credential Exposure to Discovered Peers
Clebert Suconic
-
CVE-2026-49363: Apache Artemis, Apache ActiveMQ Artemis: Pre-Authentication Information Disclosure in CORE Protocol Topology Subscription
Clebert Suconic
-
CVE-2026-57822: Apache Artemis, Apache ActiveMQ Artemis: Message-based management parameter deserialization may lead to denial of service
Clebert Suconic
-
CVE-2026-75880: Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to denial of service
Clebert Suconic
-
[ANNOUNCE] Release Apache DolphinScheduler 3.4.3
wenjun
-
CVE-2026-54048: Apache Impala: Avro Schema URL Server-Side Request Forgery
Michael Smith
-
CVE-2026-57866: Apache Impala: Secrets Exfiltration via SSRF
Michael Smith
-
CVE-2026-56207: Apache Impala: SAML authentication bypass via forged bearer token
Michael Smith
-
CVE-2026-65181: Apache Impala: RCE via External Data Source Class Loading
Michael Smith
-
[ANNOUNCE] Apache Impala 4.5.2 release
Michael Smith
-
[ANNOUNCE] Apache Arrow Go v18.8.0 Released
Matt Topol
-
CVE-2026-75156: Apache Airflow FAB provider: FAB Azure AD OAuth: id_token issuer/audience not validated — cross-tenant authentication bypass
Niko Oliveira
-
CVE-2026-74761: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId
Matt Pavlovich
-
CVE-2026-41871: Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)
Sebastian Nagel
-
CVE-2026-41870: Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)
Sebastian Nagel
-
CVE-2026-41869: Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch REST API)
Sebastian Nagel
-
[ANNOUNCE] Apache Nutch 1.23 Release
Sebastian Nagel
-
CVE-2026-84939: Apache FreeMarker: A malformed locale may be exploitable for path traversal attacks
Dániel Dékány
-
[ANN] Apache Tomcat Native 1.3.9 released
Mark Thomas
-
[ANN] Apache Tomcat Native 2.0.16 released
Mark Thomas
-
[ANNOUNCE] Apache Groovy 6.0.0-RC-1 Released
Paul King
-
[ANNOUNCE] Apache PLC4X 1.0.0 released
Christofer Dutz
-
[ANNOUNCE] Apache Groovy 5.1.2 Released
Paul King
-
CVE-2026-78254: Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file write
Stefan Bodewig
-
[ANN] Apache Ant 1.10.18 Released
Stefan Bodewig
-
[ANNOUNCE] Apache Commons Secure XML 1.0.0
Gary Gregory
-
CVE-2026-52691: Apache Griffin Hive Metastore Module: SQL Injection Vulnerability in Hive Metastore Module
Arnout Engelen
-
[ANNOUNCE] Apache Fory 1.7.1 released
Shawn Yang
-
[ANNOUNCE] Release Apache OpenDAL 0.59.0
Xuanwo
-
CVE-2026-71216: Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key over cleartext HTTP
Kai Wan
-
CVE-2026-85229: Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incomplete fix of CVE-2025-54057)
Sheng Wu
-
CVE-2026-80180: Apache Allura: Stored XSS via markdown HTML processing
Dave Brondsema
-
CVE-2026-80181: Apache Allura: Server-side request forgery
Dave Brondsema
-
CVE-2026-81270: Apache Allura: Information exposure via search
Dave Brondsema
-
CVE-2026-80190: Apache Allura: Stored XSS via code repositories
Dave Brondsema
-
[ANNOUNCE] Apache Allura 1.21.0 released
Dave Brondsema
-
[ANNOUNCE] Apache ActiveMQ v6.3.2 has been released!
Matt Pavlovich
-
[ANNOUNCE] Apache CloudStack Regular Release 4.23.0.0
Wei Zhou
-
Apache Beam 2.76.0 Released!
Vitalii Terentev
-
CVE-2026-32773: Apache Spark: XSS Vulnerability in Spark Web 3.5.4
Holden Karau
-
[ANNOUNCE] Apache NetBeans 31 Released
Eric Barboni
-
[ANNOUNCE] Apache Fory 1.7.0 released
Shawn Yang
-
CVE-2026-76983: Apache Wicket: XSS in AutoLabelTextResolver via FormComponent.setLabel
Emond Papegaaij
-
CVE-2026-76985: Apache Wicket: XSS in Palette via getAdditionalAttributes
Emond Papegaaij
-
CVE-2026-76986: Apache Wicket: XSS in AbstractSingleSelectChoice via getNullValidDisplayValue
Emond Papegaaij
-
CVE-2026-76984: Apache Wicket: XSS in MetaDataHeaderItem via addTagAttribute
Emond Papegaaij
-
CVE-2026-76982: Apache Wicket: XSS in Button via its model object
Emond Papegaaij
-
CVE-2026-75802: Apache Wicket: XSS in AjaxEditableLabel and its subclasses via IChoiceRenderer and defaultNullLabel
Emond Papegaaij
-
CVE-2026-58301: Apache Shiro: Server-side POST request may be steered to an alternate host
Lenny Primak
-
CVE-2026-71257: Apache Wicket: Configured file upload limits are not enforced when the multipart request has already been parsed
Emond Papegaaij
-
CVE-2026-71378: Apache Wicket: Cross-Site Request Forgery (CSRF) protection bypass in ResourceIsolationRequestCycleListener
Emond Papegaaij
-
CVE-2026-70449: Apache Wicket: Path traversal in resource style/variation/locale
Emond Papegaaij
-
[ANNOUNCE] Apache Wicket 10.11.0 released
Andrea Del Bene
-
[ANNOUNCE] Apache Wicket 9.24.0 released
Andrea Del Bene
-
[ANNOUNCE] Apache Wicket 8.19.0 released
Andrea Del Bene
-
[ANNOUNCE] Apache Airflow Providers prepared on 2026-08-25 are released
Niko Oliveira
-
[ANNOUNCE] Apache Grails 8.0.0-M6
Mattias Reichel
-
[ANNOUNCE] Apache Burr (Incubating) 0.43.0 released
Jernej Frank
-
[ANNOUNCE] Apache FreeMarker 2.3.35 is released
Daniel Dekany
-
[ANNOUNCE] Apache SkyWalking 11.0.0 released
Kai Wan
-
[ANNOUNCEMENT] Apache SkyWalking BanyanDB 0.11.0 Released
hanahmily
-
[ANNOUNCE] Apache Ozone 2.2.1 released
Wei-Chiu Chuang
-
[ANNOUNCE] Apache Shiro 3.0.1 released
Lenny Primak
-
[ANNOUNCE] Apache Artemis 2.56.0 Released
Domenico Francesco Bruscino
-
[ANNOUNCE] Apache Groovy 6.0.0-beta-3 Released
Paul King
-
[ANNOUNCE] Apache Groovy 5.1.1 Released
Paul King
-
[ANNOUNCE] Apache Grails 7.2.3
James Daugherty
-
[ANNOUNCE] Apache Grails 7.1.6
James Daugherty
-
[ANNOUNCE] Apache Grails 7.0.16
James Daugherty
-
[ANNOUNCE] Apache XTable 0.4.0-incubating released
Vinish Reddy
-
CVE-2026-55976: Apache Hive: SSRF vulnerability in Hive Avro Serde due to Insufficient input validation on avro.schema.url
Sai Hemanth Gantasala
-
CVE-2026-53561: Apache Hive: Unauthenticated authentication bypass in HiveServer2 HTTP SAML bearer-token validation allows impersonation of any Hive user
Sai Hemanth Gantasala
-
CVE-2026-49845: Apache Hive: SQL Injection vulnerability in HiveMetaStore partition-name direct-SQL paths
Sai Hemanth Gantasala
-
CVE-2026-75005: Apache APISIX: Unauthenticated CPU-exhaustion DoS
Abhishek Choudhary
-
CVE-2026-75020: Apache APISIX: ldap-auth plugin cross-subtree identity impersonation
Abhishek Choudhary
-
CVE-2026-74848: Apache APISIX: Cross-user response poisoning in serverless plugins
Abhishek Choudhary
-
[ANNOUNCE] Apache Pulsar C# Client DotPulsar 5.3.3 released
David Jensen
-
CVE-2026-63041: Apache APISIX: attach-consumer-label does not strip client-supplied consumer-label headers
Abhishek Choudhary
-
[ANNOUNCE] Apache APISIX 3.18.0 has been released
Abhishek Choudhary
-
[SECURITY] CVE-2026-68569 Apache Tomcat - Principal lookup can fail open in some cases
Mark Thomas
-
[SECURITY] CVE-2026-73180 Apache Tomcat - Authenticated WebSocket session survives end of HTTP session
Mark Thomas
-
[SECURITY] CVE-2026-68763 Apache Tomcat - DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset
Mark Thomas
-
[SECURITY] CVE-2026-68525 Apache Tomcat - Redirect after FORM authentication may bypass method specific constraints
Mark Thomas
-
[SECURITY] CVE-2026-66422 Apache Tomcat - Servlet role references can bypass declarative role constraints
Mark Thomas
-
[SECURITY] CVE-2026-65637 Apache Tomcat - HTTP/2 no-authority bypass of strict SNI validation
Mark Thomas
-
[SECURITY] CVE-2026-65927 Apache Tomcat - RewriteValve [N] restarts at the second rule and may bypass access control
Mark Thomas
-
[SECURITY] CVE-2026-65905 Apache Tomcat - Limited replay attack possible with DIGEST authentication
Mark Thomas
-
[SECURITY] CVE-2026-65182 Apache Tomcat - Security constraint bypass
Mark Thomas
-
[SECURITY] CVE-2026-65183 Apache Tomcat - TOCTOU when setting specific permissions for Unix Domain Sockets
Mark Thomas
-
[ANNOUNCE] Apache XMLBeans 5.4.0 release
PJ Fanning
-
Fwd: [ANNOUNCE] Apache Hive 4.2.1 Released
Sai Hemanth Gantasala
-
CVE-2026-66906: Apache Camel: Camel-Azure-Storage-Blob: the downloadBlobToFile operation built the local download target from the remote blob name without constraining it to the configured fileDir
Andrea Cosentino
-
[ANNOUNCE] Apache Allura 1.20.0 released
Dave Brondsema
-
CVE-2026-75099: Apache Allura: Unauthenticated REST disclosure
Dave Brondsema
-
CVE-2026-66907: Apache Camel: Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
Andrea Cosentino
-
CVE-2026-63621: Apache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategy
Andrea Cosentino
-
CVE-2026-71300: Apache Camel: Camel-Atmosphere-Websocket: WebSocket dispatch header injection
Andrea Cosentino
-
CVE-2026-60093: Apache Camel: Camel-Azure-Storage-DataLake: the downloadToFile operation built the local download target from the remote path name without constraining it to the configured fileDir
Andrea Cosentino
-
CVE-2026-59230: Apache Camel: Camel-Mail: the MimeMultipart data format copied MIME headers onto the Camel message without a header filter strategy when unmarshalling with headersInline enabled
Andrea Cosentino
-
CVE-2026-66908: Apache Camel: Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
Andrea Cosentino
-
CVE-2026-78329: Apache Camel: Camel-Undertow: the endpoint discarded the undertow-specific header filter strategy in favour of the base HTTP one, so the undertow filtering never ran on endpoint-configured routes
Andrea Cosentino
-
[ANN] Maven Resolver 2.0.22 Released
Tamás Cservenák
-
[ANNOUNCE] Apache Airflow Providers prepared on 2026-08-18 are released
Hussein Awala
-
Fwd: [ANNOUNCE] Apache JSPWiki 3.0.0 released
Alex O'Ree
-
Fwd: [ANNOUNCE] Apache JSPWiki 2.12.5 released
Alex O'Ree
-
[ANNOUNCE] Apache Avro 1.12.2 released
Ryan Skraba
-
[ANNOUNCE] Apache Pekko Connectors Kafka 1.2.0 released
PJ Fanning
-
[ANNOUNCE] Apache SedonaDB 0.4.1 released
Jia Yu
-
[ANNOUNCE] Apache Tika 4.0.0 released
Tim Allison
-
[ANNOUNCE] Apache log4net 3.4.0 released
Jan Friedrich
-
[ANNOUNCE] Apache Casbin (Incubating) 3.11.0 released
Yanrui Zhang
-
[ANNOUNCE] Release Apache Paimon Vector Index 0.4.0
jerry jing
-
[ANNOUNCE] Apache Pekko (Core) 1.7.0 released
PJ Fanning
-
[ADVISORY] Apache CloudStack LTS Security Releases 4.20.3.1 and 4.22.1.1
Abhishek Kumar
-
[ANNOUNCE] Release Apache OpenDAL 0.58.2
Erick Guan
-
CVE-2026-63038: Apache InLong: SQL Injection via String Concatenation Vulnerability Report
Charles Zhang
-
CVE-2026-63042: Apache InLong: Missing authorization on DataNode management endpoints
Charles Zhang
-
CVE-2026-63043: Apache InLong: Agent path traversal via unvalidated file source path
Charles Zhang
-
CVE-2026-63040: Apache InLong: Missing authorization in StreamSource forceDelete
Charles Zhang